First published: Sun Apr 20 2025(Updated: )
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kitty Kitty | <0.41.0 | |
Kovidgoyal Kitty | <0.41.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43929 is classified as a high severity vulnerability due to the risk of executing potentially harmful local files without user consent.
To fix CVE-2025-43929, update to version 0.41.0 or later of the Kitty software, which implements user confirmation for executing local files.
CVE-2025-43929 affects versions of Kitty prior to 0.41.0, particularly when linked documents come from untrusted sources.
CVE-2025-43929 is a local executable execution vulnerability that allows unintended execution of files through external documents.
Users of Kitty prior to version 0.41.0, especially those using it in conjunction with untrusted documents from applications like KDE Ghostwriter, are impacted by CVE-2025-43929.